CVE-2024-22036

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
16/04/2025
Last modified:
15/04/2026

Description

A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot<br /> jail and gain root access to the Rancher container itself. In <br /> production environments, further privilege escalation is possible based <br /> on living off the land within the Rancher container itself. For the test<br /> and development environments, based on a –privileged Docker container, <br /> it is possible to escape the Docker container and gain execution access <br /> on the host system.<br /> <br /> <br /> This issue affects rancher: from 2.7.0 before 2.7.16, from 2.8.0 before 2.8.9, from 2.9.0 before 2.9.3.